Back

CVE-2001-0187

Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.

Published: Mar 26, 2001 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (19)

Vendor Product Version
washington_university wu-ftpd 2.4.1
washington_university wu-ftpd 2.4.2_beta9
washington_university wu-ftpd 2.4.2_beta18
washington_university wu-ftpd 2.4.2_beta18_vr4
washington_university wu-ftpd 2.4.2_beta18_vr5
washington_university wu-ftpd 2.4.2_beta18_vr6
washington_university wu-ftpd 2.4.2_beta18_vr7
washington_university wu-ftpd 2.4.2_beta18_vr8
washington_university wu-ftpd 2.4.2_beta18_vr9
washington_university wu-ftpd 2.4.2_beta18_vr10
washington_university wu-ftpd 2.4.2_beta18_vr11
washington_university wu-ftpd 2.4.2_beta18_vr12
washington_university wu-ftpd 2.4.2_beta18_vr13
washington_university wu-ftpd 2.4.2_beta18_vr14
washington_university wu-ftpd 2.4.2_beta18_vr15
washington_university wu-ftpd 2.4.2_vr16
washington_university wu-ftpd 2.4.2_vr17
washington_university wu-ftpd 2.5
washington_university wu-ftpd 2.6

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 8.92%

Top 7% most likely to be exploited

Threat Score 42.7 / 100

Data Sources

NVD EPSS